HIPAA-aware website infrastructure
Patient inquiry forms must capture data through HIPAA-compliant channels (BAA-signed email providers, encrypted storage, audit logging). Google Analytics 4 with HIPAA-aware configuration (no PHI in event parameters). Heat-mapping tools (Hotjar, Microsoft Clarity) configured to mask PHI inputs. The website infrastructure is non-negotiable foundation work.